SendXa
← Back to sending files

Privacy — SendXa

This page explains where your files go, what we keep, and for how long.

Last updated: 23 August 2026

File contents never rest on our server

When the receiver hits download, the server joins the two ends and pushes bytes across. Not one byte is written to disk. Your file exists only on the sending and receiving computers. There is no place on the server for a session's file to be written, so this does not rest on us keeping our word.

When the two computers connect directly

If the network allows it, the two browsers connect straight to each other and the file never passes through our server at all. The server then only introduces the two sides to one another.

One exception: the 24-hour route

Every file row has a cloud button, for when the other machine is not online. You have to press it yourself, and the page spells out how it differs first. Once you do, the receiving side fetches the server copy on its own when it cannot reach your machine. On this route the files ARE written to our disk, and anyone with the link can download them without an ID or a code. They delete themselves after 24 hours, up to 500 MB per file. This route keeps its own log of file name, size, timestamp and the uploader's IP address, so abuse can be traced. The section at the top of this page, about files never resting on our server, describes the direct route; this is the one exception, and it never happens on its own.

If you need more, lock the file yourself before sending

The page used to carry a Lock with my own password option; it was removed on 25 August 2026 because it only worked on files under 100 MB. Instead: zip the file with a password using whatever archiver is already on your machine, send the archive, and pass the password along some other way. We do not learn that password and cannot open the file.

What the server does keep

While a session is open the server keeps: the session's 8-character code, file names and sizes (so the receiver can see the list before downloading), the time the session was created, and a side marker recording which device added which item. That marker means nothing outside the session and cannot say who you are. Never file contents. All of it is deleted when the session closes, or after 12 hours at the latest.

Operational logs

The server writes operational logs containing IP addresses, timestamps, and the number of files in a session, used to diagnose faults and block abuse. For the direct route these logs contain no file names and no file contents. The 24-hour route keeps its own log, and that one DOES record file names, as described above.

No accounts, no tracking

No sign-up, no password, no user profile. The page carries no third-party tracking, no ads, and we sell data to no one.

What your browser stores on your machine

Your language, light or dark background, and list layout stay in browser storage until you clear them. The ID, code and ticket of an open session live in storage belonging to that one tab, which is why a reload does not ask you to type them again; close the tab and they are gone. There are no cookies, and none of this is sent to the server.

The 8-character code protects your session

Anyone with the code can join, and anyone who joins can also add files. Send it over a channel you trust, to the person you mean to exchange with, and do not post it publicly.

Your rights

Because we hold no account or profile for you, there is almost no personal data to request or erase. If you want a session gone right now, close it. Everything about it is deleted at once.